Developer tools
Use shared authentication, SDK configuration, error, and webhook conventions across provider-specific integrations.
On this page
Shared developer contracts
Authentication
Separate human sign-in, Carden keys, provider credentials, tenants, environments, and scopes.
Server SDKs
Review seven-language release status, installation, and client configuration.
Errors
Interpret common HTTP response classes and retry only safe operations.
Webhooks
Verify provider events and outbound Carden notifications at separate trust boundaries.
Provider request fields and workflow instructions stay with the provider being implemented. Shared material appears here only when the behavior is the same across QuickBooks, Stripe, and Square.
HTTP conventions
Send server-to-server requests over HTTPS to the Carden deployment origin. Use a provider-integration Carden key in Authorization: Bearer. Dashboard sessions and provider credentials cannot substitute for that key.
Authorization: Bearer <CARDEN_API_KEY>
Content-Type: application/json
Accept: application/jsonMoney fields ending in Minor use integer minor units with explicit currency. Preserve timezone-aware timestamps and stable identities across retries. Retain x-carden-request-id as a diagnostic value, never as payment idempotency.
Open the provider API
| Provider | API pages |
|---|---|
| QuickBooks | Invoice lookup/provenance and connection/sync operations. |
| Stripe | PaymentIntent enrichment and payment-report resources. |
| Square | Order enrichment and Payment-report resources. |
QuickBooks invoice data
Read imported invoices and immutable source evidence.
QuickBooks API
Manage consent invitations and asynchronous sync work.
Stripe enrichment API
Prepare inline PaymentIntent commercial fields.
Stripe reports API
Deliver immutable observed payment states.
Square API
Prepare Orders and report Payments.